Simple script to copy secrets from one Hashicorp Vault instance to another. Origin Policy # dump-read path "secret/*" { capabilities = ["read", "list"] } vault token create -policy=dump-read -period=30m Destiny Policy # dump-create path "secret/*" { capabilities = ["create", "update"] } vault token create -policy=dump-create -period=30m